Skip to content

AKS Learn feedback: Details regarding Container Network Logs config #251

Open
@audunsolemdal

Description

@audunsolemdal

Type of issue

Missing information

Feedback

First of all, very happy to finally have these logs available in log analytics - thank you!

  1. I am able to get data into my RetinaNetworkFlowLogs log analytics table as long as I follow this part of the guide strictly

However, enabling the AKS monitoring addon creates a DCR with a lot of costly logs which I am not interested in ingesting (yes I know it can be configured via configmap, but it is a hassle). After editing the DCR I am not seeing any new entries in the RetinaNetworkFlowLogs table no matter what I configure. Is it possible to configure the DCR at all, so that only RetinaNetworkFlowLogs are ingested to log analytics?

  1. It is also unclear if the --enable-high-log-scale-mode flag is actually required or reccomended for enablement. Personally I am just interested in RetinaNetworkFlowLogs for records which are Dropped.

  2. Is it possible to exclude traffic to/from specific IP CIDRs from being logged? E.g. I am seeing some dropped IPv6 traffic dropped due to dual stack not being enabled on my cluster. UNSUPPORTED_L3_PROTOCOL. There may also be traffic to specific IPv4 addresses which I do not care about logging

Page URL

https://learn.microsoft.com/en-us/azure/aks/how-to-configure-container-network-logs?tabs=cilium

Content source URL

https://github.com/MicrosoftDocs/azure-aks-docs/blob/main/articles/aks/how-to-configure-container-network-logs.md

Author

@shaifaligargmsft

Document Id

b7810c57-10eb-1e22-258f-050df903a3a4

Platform Id

5aa15265-0850-2034-6e64-f7539c7c96fb

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions